CVE-2026-26133

HIGHCVSS 7.1/10EPSS 0.43%

Last modified

CVE-2026-26133 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.

Description

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Metrics

CVSS 3.1
7.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

EPSS Probability
0.43%

34.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Microsoft365 Copilot< 2.107.2
Microsoft365 Copilot< 16.0.19815.10000
MicrosoftEdge< 145.3800.99
MicrosoftExcel< 2.106.2
MicrosoftExcel< 16.0.19822.20038
MicrosoftLoop< 2.106
MicrosoftOnenote< 16.0.19725.20142
MicrosoftOnenoteAll versions
MicrosoftOutlook< 5.2605.0
MicrosoftOutlookAll versions
MicrosoftPower Bi< 2.2.260210.21290750
MicrosoftPower BiAll versions
MicrosoftPowerpoint< 2.106.2
MicrosoftPowerpoint< 16.0.19822.20038
MicrosoftTeams< 1.0.0.2026043102
MicrosoftTeams< 8.3.1
MicrosoftWord< 2.106.2
MicrosoftWord< 16.0.19822.20038

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2026-26133?
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
How severe is CVE-2026-26133?
CVE-2026-26133 has a CVSS score of 7.1/10 (HIGH severity). The EPSS model estimates a 0.43% probability of exploitation in the next 30 days.
How do I fix CVE-2026-26133?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2026-26133?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST